MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e2957e5fefe511cbabd0912d944bddd0b625af1d03f5dd73e1bb61322a579b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2e2957e5fefe511cbabd0912d944bddd0b625af1d03f5dd73e1bb61322a579b8
SHA3-384 hash: de727684a248de8948ec84f272adb89adc3ce8ea10a8f01b9cb9ae0ef3b4995ce5042f55aa843692b5f3e4f592ed2109
SHA1 hash: fe864ec59435fbf4959b54c0897ee26a5ff2c068
MD5 hash: 624ab6098b89b4c811ca792f585c862b
humanhash: wisconsin-triple-oregon-single
File name:PaymentNotification.rar
Download: download sample
Signature AgentTesla
File size:454'757 bytes
First seen:2020-08-13 13:44:02 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:nEwOhlA2vfIJsWqrurGMVgOOx7VExJ48Nyjh:nEwcG24JB8xBWJ4Z
TLSH C9A4230DF61988023AD8734F90468D6CA6BB1488F9616DB383DF05C456DBEFD73B9A84
Reporter abuse_ch
Tags:AgentTesla rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: gree.com
Sending IP: 45.127.62.51
From: Manager <nina@barberajmeagher.gq>
Subject: payment
Attachment: PaymentNotification.rar (contains "PaymentNotification.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-08-13 13:45:08 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 2e2957e5fefe511cbabd0912d944bddd0b625af1d03f5dd73e1bb61322a579b8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments